[NEWS] Kazaa and Morpheus Expose Sensitive Information
From: support@securiteam.comDate: 08/29/01
- Previous message: support@securiteam.com: "[NT] TrendMicro OfficeScan Corp Edition Remote File Reading Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Subject: [NEWS] Kazaa and Morpheus Expose Sensitive Information Message-Id: <20010829184957.8B803138BF@mail.der-keiler.de> Date: Wed, 29 Aug 2001 20:49:57 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Kazaa and Morpheus Expose Sensitive Information
------------------------------------------------------------------------
SUMMARY
Kazaa and Morpheus allow users to easily search, share, discover, create,
and communicate with other users. These products reveal sensitive
information about the remote host, and the username that is currently
being used by the remote client.
DETAILS
Example:
# telnet morpheus.users.ip.address
Trying morpheus.users.ip.address...
Connected to morpheus.users.ip.address.
Escape character is '^]'.
GET / HTTP/1.0
HTTP/1.0 200 OK
X-Kazaa-Username: {USER NAME HERE}
X-Kazaa-Network: MusicCity
X-Kazaa-IP: morpheus.users.ip.address:1214
X-Kazaa-SupernodeIP: 130.74.237.54:1214
ADDITIONAL INFORMATION
The information has been provided by <mailto:jsunday@parview.com> Jesse
Sunday.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NT] TrendMicro OfficeScan Corp Edition Remote File Reading Vulnerability"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]